โ๏ธ TI-2026-026F โ The Sanctions Question: Iranian Transit Through German Infrastructure
Executive Summary: In June 2026, four Iranian LIRs began routing internet traffic through AS198584 โ a German ASN operated by PIO-Hosting GmbH (which is, as we've demonstrated, XSServer GmbH in disguise). EU Council Regulation 267/2012 prohibits making "economic resources" available to designated Iranian entities. Internet transit is an economic resource. This final installment examines the legal framework, the plausible deniability structure, and asks the hardest question: is this sanctions evasion hiding in plain sight, or is the entire German "gray transit" sector a legal gray zone that no regulator has chosen to clarify?
Chapter 1: The Observable Facts
BGP routing data shows the following Iranian-registered prefixes transiting via AS198584 (PIO-Hosting GmbH, Germany):
| LIR Maintainer | Prefix | First Seen | Contact Pattern |
|---|---|---|---|
| lir-ir-salehi-1-MNT | 91.206.28.0/24 | June 2026 | Iranian naming convention |
| lir-ir-seyeddavood-1-MNT | 185.43.33.0/24 | June 2026 | Iranian naming convention |
| lir-ir-mazdab-1-MNT | 91.207.x.0/24 | June 2026 | Iranian naming convention |
| lir-ir-nahor-1-MNT | Various | June 2026 | Iranian naming convention |
| InterLIR (Iranian contact) | 212.102.x.0/24 | June 2026 | Marketplace-brokered |
The lir-ir- naming convention in RIPE identifies Iranian Local Internet Registries. These are organizations in Iran that have RIPE NCC membership and manage IP address allocations. They are by definition Iranian entities.
All four appeared within the same month โ June 2026 โ suggesting a bulk onboarding arrangement rather than individual customer acquisitions over time.
The fifth entry (InterLIR) indicates the involvement of an IP address marketplace as a broker โ potentially IPXO/InterLIR facilitating the connection between Iranian LIRs and German transit.
Chapter 2: EU Sanctions Law โ What It Actually Says
EU Council Regulation (EC) No 267/2012 (consolidated with amendments through 2026) imposes comprehensive restrictive measures against Iran. The relevant provisions:
Article 23(2):
"No funds or economic resources shall be made available, directly or indirectly, to or for the benefit of [...] natural or legal persons, entities or bodies listed in Annex IX."
Article 1(i) โ Definition of "economic resources":
"assets of every kind, whether tangible or intangible, movable or immovable, which are not funds but may be used to obtain funds, goods or services"
Internet transit โ bandwidth, routing, connectivity โ is an intangible asset that can be used to obtain services. It falls within this definition.
German implementation โ Auรenwirtschaftsgesetz (AWG) ยง18:
"Whoever willfully violates a directly applicable prohibition [...] shall be punished with imprisonment of not less than one year and not more than ten years."
The critical question: are the Iranian LIRs routing through PIO-Hosting designated entities (listed in Annex IX), or are they private companies not covered by the sanctions regime?
โ Are all Iranian companies sanctioned, or only specific ones?
Only entities listed in Annexes VIII and IX of Regulation 267/2012. Not every Iranian company is sanctioned. The sanctions target specific entities connected to nuclear proliferation, IRGC, and designated banks. However, Article 23(3) extends to entities "owned or controlled by" designated persons โ and in Iran, the IRGC has economic interests in all major sectors including telecommunications. The question for PIO-Hosting is: did they verify that their Iranian LIR customers are NOT controlled by designated entities? Under EU sanctions compliance, the burden of proof is on the provider.
Chapter 3: Due Diligence โ What PIO-Hosting Should Have Done
Under EU sanctions regulations, any entity providing services to potentially sanctioned persons must conduct Know Your Customer (KYC) due diligence. For PIO-Hosting, this would require:
- Identify the customer: Determine who controls the Iranian LIR
- Screen against sanctions lists: Check EU Consolidated List, OFAC SDN, UN sanctions
- Determine beneficial ownership: Identify the natural persons who own/control the entity
- Assess the risk: Iranian telecommunications entities have elevated risk due to IRGC involvement
- Document the decision: Maintain records of compliance checks
The observable evidence suggests none of this occurred:
- Bulk onboarding: Four LIRs in one month suggests a marketplace deal, not individual KYC processes
- No public compliance program: PIO-Hosting's website mentions no sanctions compliance
- Known bulletproof operation: A company already hosting C2 panels and reputation launderers is unlikely to have a compliance department
- InterLIR marketplace involvement: Suggests the broker handled the connection, removing PIO from direct customer contact
The German regulator responsible for sanctions enforcement is BAFA (Bundesamt fรผr Wirtschaft und Ausfuhrkontrolle โ Federal Office for Economic Affairs and Export Control). They issue specific guidance on due diligence requirements. PIO-Hosting, as a German GmbH, is subject to BAFA oversight.
๐ Read Between the Lines
- The "marketplace" intermediary (InterLIR/IPXO) serves as a compliance buffer. PIO-Hosting can claim: "Our customer is InterLIR (Lithuanian company), not Iranian entities." But Article 23(2) says "directly or indirectly" โ the word "indirectly" was included precisely to prevent this kind of layering.
- The timing (June 2026) coincides with EU-Iran tensions over the nuclear deal. Sanctions enforcement typically tightens during political tensions. Onboarding Iranian customers at this moment is either reckless or deliberate.
- BAFA's enforcement record for internet services is essentially zero. They focus on physical goods (dual-use technology, weapons components). Digital services โ hosting, transit, cloud โ exist in an enforcement gap. This isn't because the law doesn't cover them; it's because the regulator hasn't built capacity for this sector.
Chapter 4: Plausible Deniability โ Five Layers Between Iran and Germany
The routing path from an Iranian LIR to the public internet passes through:
Iranian LIR (e.g., lir-ir-salehi)
โ IP blocks registered to Iranian entity
InterLIR Marketplace (Lithuania?)
โ Broker arranges transit
PIO-Hosting GmbH (Germany, AS198584)
โ BGP announcement
SkyLink Data Center BV (Netherlands, AS44592)
โ Upstream transit
Tier-1 carriers โ Internet
Each layer provides deniability:
| Entity | Defense |
|---|---|
| Iranian LIR | "We bought legitimate internet services" |
| InterLIR marketplace | "We're a platform; we don't screen end-users of transit" |
| PIO-Hosting | "Our customer is [marketplace], not Iran" |
| SkyLink | "We provide upstream to PIO; we don't know their customers" |
| Tier-1 carriers | "We peer with SkyLink; due diligence stops at our customer" |
Every entity claims the person next to them is responsible. Nobody claims responsibility for the end-to-end chain. This is the distributed irresponsibility that makes internet sanctions enforcement nearly impossible.
โ Has any internet company ever been prosecuted under EU Iran sanctions for providing transit?
To our knowledge: no. EU sanctions prosecutions focus on banks (Standard Chartered: $1.1B fine), oil traders, and weapons manufacturers. The digital services sector has avoided prosecution entirely โ not because it's compliant, but because regulators lack the technical capacity to trace BGP routing paths and understand the relationship between ASNs, LIRs, and prefix announcements. The infrastructure is opaque by design, and regulators haven't invested in making it transparent.
Chapter 5: The Iranian LIRs โ Who Are They?
The lir-ir- naming convention tells us these are RIPE NCC members operating from Iran. But identifying the actual organizations behind the maintainer names requires deeper investigation:
| Maintainer | Name Fragment | Possible Entity Type |
|---|---|---|
| lir-ir-salehi | Salehi (common surname) | Individual or small ISP |
| lir-ir-seyeddavood | Seyed Davood (given name) | Individual or family business |
| lir-ir-mazdab | Mazdab (company name?) | Corporate entity |
| lir-ir-nahor | Nahor (name/brand) | Unknown |
Iranian ISPs and telecoms have complex ownership structures. Major carriers (Iran Telecom, MCI, Irancell) are partially state-owned and have IRGC board members. Smaller ISPs often have opaque ownership that may include IRGC-linked investment funds.
Without comprehensive KYC (which PIO-Hosting evidently didn't perform), it's impossible to determine whether these LIRs are:
- Scenario A: Legitimate private Iranian businesses needing European connectivity (legal, requires no license)
- Scenario B: Entities partially owned by IRGC-linked investment vehicles (illegal without specific license from BAFA)
- Scenario C: Front companies for sanctioned telecommunications infrastructure (criminal offense under ยง18 AWG)
The problem: scenarios B and C look identical to scenario A from the outside. Only comprehensive due diligence can distinguish them. PIO-Hosting's business model makes due diligence unprofitable.
Chapter 6: The Enforcement Gap โ Why Nothing Happens
Germany has robust sanctions enforcement for traditional sectors. BAFA processed 12,000+ export license applications in 2023. The Zoll (customs) intercepts prohibited goods. Banks employ thousands of compliance officers.
But for internet services:
| Traditional Sector | Internet Sector |
|---|---|
| Physical goods โ customs inspection | Data packets โ no border control |
| Bank transfer โ SWIFT message (traceable) | BGP announcement โ technical (opaque) |
| Export license โ BAFA application | Transit agreement โ no licensing required |
| Shipping records โ paper trail | Routing tables โ ephemeral, deletable |
| Compliance officers โ legally mandated | Abuse contacts โ no legal standard |
The regulatory apparatus was built for the physical economy. The digital economy operates in the gap between laws (which cover it) and enforcement (which doesn't reach it).
BAFA has no BGP monitoring capability. They cannot independently verify that a German ASN is routing Iranian traffic. They would need to be told โ by a complaint, by intelligence services, or by investigative journalism.
This dossier constitutes such notification.
โ Could this investigation trigger actual enforcement?
Potentially. Under German law, ยง138 StGB (failure to report planned serious offenses) doesn't apply to sanctions violations specifically. But BAFA accepts anonymous tips and investigates on its own authority. The evidence here โ four Iranian LIRs, verifiable BGP data, a known bulletproof operator โ meets the threshold for a BAFA inquiry. Whether it leads to prosecution depends on (a) identifying the specific Iranian entities and (b) proving PIO-Hosting knew or should have known about the sanctions risk. Given their broader bulletproof operation, the "should have known" standard is easily met.
Chapter 7: Iran's Internet โ The Broader Context
Iran's internet infrastructure is deliberately isolated. The state controls international gateways through the Telecommunication Infrastructure Company (TIC). During protests (2019, 2022), authorities demonstrated they can cut internet access entirely.
Why would Iranian entities need German transit? Several scenarios:
- Censorship circumvention: VPN/proxy services for Iranian citizens (arguably humanitarian)
- Sanctions evasion: Iranian companies accessing services that geo-block Iranian IPs
- Intelligence operations: State-linked actors need infrastructure outside Iranian address space
- Commercial hosting: Iranian businesses wanting European server locations for latency
- Cybercrime: Iran-based threat actors (APT33, APT34) using European infrastructure for operations
The moral complexity: the same infrastructure that enables sanctions evasion by IRGC-linked entities might also enable ordinary Iranians to access the uncensored internet. The technology is neutral. The intent determines legality. But PIO-Hosting's customer mix (C2 panels, reputation launderers, bulletproof hosting) suggests they're not in the business of supporting human rights.
๐ Read Between the Lines
- Iran's APT groups (Charming Kitten, OilRig, MuddyWater) consistently need European hosting for their operations. They target European and American organizations from European infrastructure to avoid triggering geographic IP alerts. PIO-Hosting's "no questions asked" model is exactly what an APT needs.
- The timing (June 2026) follows a pattern: Iranian LIR acquisition spikes during periods of political tension when existing providers quietly terminate Iranian customers. The demand doesn't disappear โ it moves to providers who don't ask questions.
- RIPE NCC's own policies allow Iranian organizations to be members. The question isn't whether Iranians can have RIPE resources (they can), but whether German companies can provide transit to those resources under EU sanctions law.
Chapter 8: What Enforcement Would Look Like
If German authorities chose to enforce:
- BAFA inquiry: Request PIO-Hosting's customer records for Iranian-registered prefixes
- KYC verification: Demand evidence of sanctions screening for Iranian customers
- Company structure investigation: Note that PIO = XSServer = SkyLink (same team, see 026C)
- Preliminary assessment: Determine if any Iranian LIR connects to Annex IX entities
- If positive: Criminal referral to Staatsanwaltschaft (state prosecution) under ยง18 AWG
- Penalties: Up to 10 years imprisonment (individuals), asset seizure, RIPE NCC membership revocation
The practical obstacles:
- BAFA has never prosecuted an internet transit case
- Prosecutors would need to understand BGP, RIPE, LIRs โ technical knowledge courts lack
- PIO's shell structure (see 026C) adds jurisdictional complexity
- The marketplace intermediary provides legal distance
Most likely outcome: BAFA sends a letter. PIO drops the Iranian routes. The LIRs move to another bulletproof provider. The cycle continues.
Chapter 9: Series Conclusion โ The Structure That Protects Itself
Over six installments, we've traced a path from our honeypot โ a single SSH brute-force attempt โ to:
- Two bulletproof ASNs allocated one month apart (026A)
- A UK shell company with a Turkish director and missing PSC filing (026B)
- Three German companies sharing a phone number and running gray transit (026C)
- A $55 million IP marketplace whose co-founder sits on the abuse policy committee (026D)
- A Panama Papers nominee director controlling IPs from the Seychelles (026E)
- Four Iranian LIRs routing through German infrastructure with zero sanctions compliance (this dossier)
The structure is not accidental. Every layer exists because the layer below it needs protection and the layer above it needs plausible deniability. Remove any single layer and the system adapts โ routes change, nominees rotate, companies re-incorporate.
This is the modern architecture of impunity: not one powerful entity above the law, but dozens of entities, each below the threshold of enforcement attention, collectively enabling operations that no single one of them would be permitted to conduct alone.
The solution requires what the structure prevents: simultaneous, coordinated, multi-jurisdictional action. Until internet governance bodies (RIPE NCC), sanctions regulators (BAFA), corporate transparency enforcers (UK Companies House), and law enforcement (BKA, NCA, Europol) act together โ in the same week, against the same network โ the phantom ASNs will continue to haunt the internet.
Our honeypot will keep recording. The data will keep accumulating. And when the coordination finally happens, the evidence will be here.
๐ Complete Series
026A: The Phantom ASN (Overview) ยท 026B: The Bulletproof Archipelago (HBING) ยท 026C: The German Gray Zone (PIO-Hosting) ยท 026D: The IP Marketplace (IPXO) ยท 026E: The Offshore Chain (Panama Papers) ยท 026F: The Sanctions Question (Iran)